CVE-2026-82964
8.8 HIGHpublic exploit availablePublished 2026-09-16 · Updated 2026-09-17
AI risk analysis
- Summary
- This flaw allows a local, low-privileged attacker to escape file isolation and escalate privileges by modifying security descriptors of virtualized files, potentially leading to SYSTEM-level access.
- Exploitability
- Exploitation requires local access and execution within the sandbox, making it moderately difficult. The attacker must have write access to virtualized files and directories.
- Blast radius
- If exploited, the impact is high, as it could lead to complete system compromise, including code execution as SYSTEM.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest version of Avast, ensuring the vulnerability is patched. If no version is provided, disable the affected sandbox feature or restrict access to the sandboxed environment.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened the virtualization target object with GENERIC_WRITE and FILE_WRITE_ATTRIBUTES only, omitting WRITE_DAC. Every attempt to apply the original DACL therefore failed, and the failure was discarded silently, leaving virtualized copies of sensitive files with permissive permissions. Because the IRP_MJ_CREATE callback additionally did not strip WRITE_DAC for sensitive directories, a sandboxed process could rewrite the security descriptor of a virtualized object, read the virtualized copy of the SAM database, extract local NTLM password hashes and execute code as SYSTEM. The absence of an IRP_MJ_SET_SECURITY callback in the driver's operation registration table is a related defense-in-depth gap, but it is not the control that prevents this attack.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-281, CWE-653, CWE-862
Public exploit & PoC references
All references
- https://github.com/MSNightmare/PrettyPrague
- https://support.avast.com/en-us/article/Update-Antivirus
- https://support.avg.com/SupportArticleView?l=en&urlname=Update-AVG-Antivirus
- https://support.norton.com/sp/en/us/home/current/solutions/v20240108175512167
- https://www.gendigital.com/us/en/contact-us/security-advisories/
- https://x.com/msnightmare2000/status/2094106041046765752
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-12410
- HIGHCVE-2026-91803
- HIGHCVE-2026-100596PoC
- HIGHCVE-2026-94411PoC
- HIGHCVE-2025-71421PoC
- CRITICALCVE-2026-0163
- HIGHCVE-2026-100580PoC
- HIGHCVE-2026-100615PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.